Cross-Site Scripting Vulnerability in OpenPanel by OpenPanel Developer
CVE-2026-85613
8.4HIGH
What is CVE-2026-85613?
OpenPanel prior to version 2.3.0 is susceptible to a cross-site scripting issue located in the unauthenticated favicon proxy endpoint, GET /misc/favicon. This vulnerability allows remote attackers to leverage malicious SVG files that contain embedded scripts. When a victim accesses the API origin, these malicious scripts can be executed in their browser context, thereby enabling potential credential theft and further exploitation of authenticated endpoints.
Affected Version(s)
openpanel 0 < 2.3.0
openpanel 2.3.0
